5
CVSSv2

CVE-2017-15644

Published: 19/10/2017 Updated: 07/11/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/INTRANET-IP:8000.

Vulnerable Product Search on Vulmon Subscribe to Product

webmin webmin

Exploits

[+] SSD Beyond Security: blogssecuriteamcom/indexphp/archives/3430 [+] Credits: John Page (aka hyp3rlinx) [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/WEBMIN-v1850-REMOTE-COMMAND-EXECUTIONtxt [+] ISR: ApparitionSec Vulnerability summary The following advisory describes t ...